Malicious PDF — malware analysis report

Static analysis result for SHA-256 6c900e6c32fa156c…

MALICIOUS

PDF

42.2 KB Created: 2020-08-20 19:55:42 +03:00 Authoring application: wkhtmltopdf 0.12.5 (via Qt 4.8.7)
MD5: b5c83cb740cf136e838a85da89234186 SHA-1: c5c72b2b8c51769dd805dce60a9ca82ecf549817 SHA-256: 6c900e6c32fa156c0b25c6f3b9080c7694e3f9bf69a49dc4ea6f70ae2ddb0634
154 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1059.007 JavaScript

The PDF contains a large number of external links, many pointing to potentially malicious redirector infrastructure like 'ttraff.ru'. The document body, though heavily obfuscated, contains URLs that are likely intended to lure the user to these malicious sites. The ML classifier strongly indicates maliciousness, and the presence of numerous PDF links suggests a link farm or redirection scheme.

Machine Learning

  • Nyx PDF Classifier malicious score 1.0000

Heuristics 4

  • PDF links to known malicious redirector infrastructure critical PDF_MALICIOUS_REDIRECTOR_LINK
    PDF contains a clickable URI to redirector infrastructure used by a known malicious PDF SEO/adware delivery campaign. These documents typically rely on user interaction and redirect chains rather than a PDF parser vulnerability.
  • Small PDF contains mass external PDF link farm critical PDF_SEO_LINK_FARM
    Small PDF contains many clickable external PDF links, mostly clustered on one host. This matches generated SEO/link-farm PDF carriers used to route users into malicious or unwanted-software delivery chains, rather than a normal document citation pattern.
  • Object number defined twice with different bodies info PDF_DUPLICATE_OBJ_BODY_INCREMENTAL
    The same indirect object (N G) is defined more than once with different body bytes. First-wins and last-wins readers will resolve different content, which is a parser-confusion shape used by targeted PDFs. Body-only differences are common in benign incremental updates, so severity is raised only when the duplicate carries active content.
  • Embedded URL info EMBEDDED_URL
    One or more URLs were extracted from the document. The URL itself is not a detection — see the per-URL labels for which channel (macro, JS, link annotation, document body, ...) reached each URL.
    URL https://ttraff.ru/pify?keyword=geneva+mechanism+mini+project+report
    • http://files.gbmochas.org/uploads/1/3/0/8/130874480/37581f4e35e9b6.pdf
    • http://xetiwut.mrsdinglesclass.com/uploads/1/3/2/8/132814930/lixututidinaf.pdf
    • http://files.jamarkllc.com/uploads/1/3/1/3/131383251/zesimizerimag.pdf
    • http://www.ascendercorp.com/
    • http://www.ascendercorp.com/typedesigners.html
    • https://cdn.shopify.com/s/files/1/0428/6559/0438/files/nodame_cantabile_torrent.pdf
    • https://cdn.shopify.com/s/files/1/0437/3420/4568/files/70634230841.pdf
    • https://cdn.shopify.com/s/files/1/0435/8366/8392/files/phoneme_segmentation_worksheets_free.pdf
    • https://cdn.shopify.com/s/files/1/0439/0672/8091/files/tuxumugukabipavez.pdf
    • https://cdn.shopify.com/s/files/1/0435/7819/6129/files/millennial_generation_research.pdf
    • https://cdn.shopify.com/s/files/1/0430/8385/8080/files/autobiography_example_format.pdf
    • https://cdn.shopify.com/s/files/1/0430/8313/7178/files/96914473972.pdf
    • https://cdn.shopify.com/s/files/1/0431/6535/2093/files/33395248552.pdf
    • https://cdn.shopify.com/s/files/1/0434/0134/7226/files/33699359711.pdf
    • https://cdn.shopify.com/s/files/1/0432/2109/0471/files/rigulixola.pdf
    • https://cdn.shopify.com/s/files/1/0433/7991/6963/files/xilajuge.pdf
    • http://www.w3.org/1999/02/22-rdf-syntax-ns#
    • http://purl.org/dc/elements/1.1/
    • http://ns.adobe.com/pdf/1.3/
    • http://ns.adobe.com/xap/1.0/
    • http://ns.adobe.com/xap/1.0/mm/
    • http://ns.adobe.com/xap/1.0/rights/
    • http://scripts.sil.org/OFL

Extracted artifacts 2

Files carved from inside the sample during analysis.

FilenameKindSourceSize
font_00_sfnt_off000067f1.bin
06aa6d8f51ffe97eec2ca77754caeaabf27ba3f8cb32a8cdb408092d5ec604b0
pdf-font-stream PDF embedded font (sfnt) at offset 0x67F1 5308 bytes
font_01_sfnt_off000079e0.bin
1f69697f96158f617235bde5844106aaa8b3078571172f0c203062b2ed80f3f1
pdf-font-stream PDF embedded font (sfnt) at offset 0x79E0 9892 bytes